Find XSS payloads that actually work by filtering them based on real-world constraints instead of blind payload spraying.
☆283Aug 12, 2026Updated 3 weeks ago
Alternatives and similar repositories for XSSNow
Users that are interested in XSSNow are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ExecEvasion is a lightweight execution-evasion toolkit that generates command variants designed to bypass naive filters and WAF rules by …☆56Jan 31, 2026Updated 7 months ago
- JWT Auditor – Analyze, break, and understand your tokens like a pro.☆591Jul 11, 2026Updated last month
- Subdomain Enumerator and Simple Crawler☆453May 22, 2026Updated 3 months ago
- ☆162Jan 22, 2026Updated 7 months ago
- NeXSS is a modern, self-hosted Blind XSS (Cross-Site Scripting) hunter and callback listener built with Next.js. It helps security resear…☆35Jan 14, 2026Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- List of Mine Private wordlist i use for fuzzing☆97Jun 17, 2026Updated 2 months ago
- ☆1,174Jan 28, 2026Updated 7 months ago
- AI-powered ffuf wrapper☆804Dec 4, 2025Updated 8 months ago
- Android APK security analysis tool. Decompiles DEX, scans for vulns, parses manifests and certs. Runs in your browser.☆72May 14, 2026Updated 3 months ago
- ☆265Dec 10, 2025Updated 8 months ago
- A comprehensive penetration testing operations dashboard for managing projects, tasks, findings, clients, and assets. Built with Next.js,…☆313May 22, 2026Updated 3 months ago
- 🔐 Chrome Extension - Detect hardcoded tokens, API keys & secrets in JavaScript files☆48Dec 15, 2025Updated 8 months ago
- ☆389Updated this week
- GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & m…☆266Mar 28, 2026Updated 5 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆35Jan 11, 2026Updated 7 months ago
- Interactive XSS Labs to get into Client-Side Hacking☆96Feb 25, 2026Updated 6 months ago
- AutoAR is an automated security reconnaissance tool, ASM and Discord bot for bug bounty hunters and penetration testers. It automates gat…☆244Aug 18, 2026Updated 2 weeks ago
- AI-powered bug bounty hunting toolkit that works with or without subscription.☆4,668Updated this week
- Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more☆1,477Updated this week
- Gather results of dorks across a number of search engines☆364Apr 23, 2026Updated 4 months ago
- An advanced Out-of-Band and In-Band SSRF fuzzing scanner with dynamic request tracking.☆40Jun 18, 2026Updated 2 months ago
- ☆540Aug 21, 2025Updated last year
- Intentionally Vulnerable Hacking Labs☆604Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 3 months ago
- High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential v…☆686Updated this week
- A tool that helps you find the real IP addresses hiding behind Cloudflare.☆642Jul 6, 2026Updated last month
- ☆201Aug 23, 2026Updated last week
- Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier☆242Jul 7, 2026Updated last month
- ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets …☆164Jul 8, 2026Updated last month
- AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)☆456Jul 4, 2026Updated last month
- Simple XSS vulnerability checker tool very useful with xsschecker.☆28Nov 21, 2025Updated 9 months ago
- Rust-powered HTTP Request Smuggling Scanner.☆129Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)☆266Dec 12, 2025Updated 8 months ago
- ☆31Jan 19, 2026Updated 7 months ago
- Auto Frida is a powerful, all-in-one automation toolkit that handles everything from Frida installation to script injection. Zero manual …☆137Apr 15, 2026Updated 4 months ago
- NeuroSploit is an advanced, AI-powered penetration testing framework designed to automate and augment various aspects of offensive securi…☆1,361Updated this week
- Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and co…☆837May 16, 2026Updated 3 months ago
- IP Finder tool, ipfinder collects IP addresses from Shodan search queries.☆17Dec 12, 2025Updated 8 months ago
- ☆259Oct 19, 2025Updated 10 months ago